Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Evolve Bank Data Breach: 7.6 Million People Reportedly Affected

Evolve Bank reported that 7,640,112 people were affected by a 2024 ransomware breach. Here’s what information may have been exposed and what the bank said about funds, monitoring, and the settlement deadline.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Evolve Bank & Trust reported that information belonging to 7,640,112 people was compromised in a 2024 ransomware incident. The bank said attackers accessed and downloaded customer information, but it found no evidence that they accessed customer funds. Those statements are not contradictory: exposed data can create identity and account risks even when the bank has not found evidence of stolen funds.

What happened in the Evolve Bank breach?

Evolve said it noticed system malfunctions in late May 2024. The bank initially suspected a hardware problem, then identified unauthorized activity and attributed the incident to LockBit ransomware. According to Evolve, an employee appeared to have clicked a malicious internet link, attackers accessed and downloaded data during periods in February and May, and some data was encrypted. Evolve said it refused the ransom demand and the stolen data was subsequently leaked. These details reflect the bank’s account of the incident, not independently established forensic findings. Evolve’s incident page and incident FAQ describe its findings.

Washington’s Attorney General lists the incident period as February 9 through May 31, 2024, and records July 8, 2024, as the report date. Evolve said it saw no new unauthorized activity after May 31. It described resetting passwords, rebuilding identity-management infrastructure, changing firewall and security monitoring, and deploying endpoint detection and response tools. The bank also said backups helped limit data loss and operational impact. Washington’s breach notice record provides the state-specific dates and affected-person count.

How many people were affected?

The reported nationwide figure is 7,640,112 individuals. SecurityWeek reported that Evolve informed Maine’s Attorney General’s Office of that count; it is a figure attributed to the bank’s disclosure, not an independently audited total. The affected group included some employees and customers of Open Banking partners. SecurityWeek’s July 9, 2024 report gives the reported national number.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Washington separately recorded 275,716 affected Washingtonians. That is a state-specific count, not an alternative estimate of the nationwide total. The Washington notice record lists the state figure.

What information may have been exposed?

Which details were involved varied by person. Evolve’s August 2024 update said information for most personal, mortgage, trust, and small-business banking customers and Open Banking partners appeared to include names, Social Security numbers, Evolve account numbers, dates of birth, and contact information. A small portion also had debit-card numbers affected. The bank said files included ACH transaction records with account and routing numbers and the names of payors and payees. Washington’s notice lists names, Social Security numbers, financial and banking information, and full dates of birth. Evolve’s update and the state notice describe the categories.

Do not assume every category applied to you. Evolve said individual notices included details about the information associated with each recipient. If you received a notice, use it to identify which data types were involved in your case.

Were customer funds impacted?

Evolve said it found no evidence that attackers accessed customer funds. In its cybersecurity incident FAQ, the bank stated: “There is no evidence that the criminals accessed any customer funds, but it appears they did access and download customer information.” Evolve’s FAQ makes that distinction explicitly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is the bank’s reported finding, not a guarantee that exposed account or identity information carries no risk. The downloaded files included some ACH records with account and routing numbers, so monitor relevant accounts and contact your financial institution promptly if you see activity you do not recognize.

Was my information affected, and what should I do?

Evolve said it began sending individual notices on July 8, 2024. Check any notice you received for the specific information involved and the instructions that apply to you. The bank’s incident guidance encouraged customers to review account activity and credit reports, set up fraud alerts, and contact Evolve if they suspected suspicious activity. It also directed people who suspect identity theft or fraud to the Federal Trade Commission or law enforcement. The bank’s incident page contains its guidance.

Evolve described a two-year offer of credit monitoring and identity-theft protection for U.S. residents as part of its 2024 response. That was a historical offer; the reviewed bank update does not establish a currently open enrollment period. A sample individual notice hosted by Massachusetts stated an October 31, 2024 enrollment deadline, but a recipient’s own notice is the relevant source for their specific offer. Evolve’s update describes the offer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is the status of the settlement?

A settlement claim form for litigation in the U.S. District Court for the Western District of Tennessee describes unauthorized access and exfiltration during February and May 2024, including information belonging to Evolve customers and fintech customers whose services used Evolve through Synapse. The form lists an October 30, 2025 claim deadline, which has passed. It describes one year of credit monitoring and options for documented losses or a flat payment. The form alone does not establish current eligibility, final approval, payment timing, or whether later court or administrator updates changed the process. The settlement site’s claim form is the source for those terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.